The Chrome browser update 79.0.3945.130 addresses four vulnerabilities, one of which has been designated as a critical issue that allows bypassing all layers of browser protection and executing code on the system beyond the sandbox environment. Details about the critical vulnerability (CVE-2020-6378) are still , known only that it is caused by accessing an already freed memory block in the speech recognition component.
The other three vulnerabilities are marked as dangerous. The vulnerability CVE-2020-6379 is also related to accessing an already freed memory block (Use-after-free) in the speech recognition code. The CVE-2020-6380 issue is caused by a message verification error from extensions. Another change relates to protection against in the Windows platform Crypto API, which allows the creation of counterfeit TLS certificates and fake digital signatures (already for generating fake certificates that are verified in Windows as trustworthy).
Source: opennet.ru
